« Volver al listado

CVE-2008-6747

Estado: ModificadaMedia (6.8)—

dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges. NOTE: some of these details are obtained from third party information.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-6747",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-04-23T17:30:01.530",
  "references": [
    {
      "url": "http://osvdb.org/46143",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/30470",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://sourceforge.net/project/shownotes.php?group_id=21656&release_id=616346",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/29679",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43019",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/46143",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/30470",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://sourceforge.net/project/shownotes.php?group_id=21656&release_id=616346",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/29679",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43019",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges.  NOTE: some of these details are obtained from third party information."
    },
    {
      "lang": "es",
      "value": "dotProject en versiones anteriores a v2.1.2 no restringe adecuadamente el acceso a las paginas de administración lo que permite a atacantes remotos conseguir privilegios. NOTA: Algunos de estos detalles fueron obtenidos de terceras partes."
    }
  ],
  "lastModified": "2026-06-16T23:02:53.637",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dotproject:dotproject:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "59F53855-341B-425B-B28D-A25C6A758D0E",
              "versionEndIncluding": "2.1.1"
            },
            {
              "criteria": "cpe:2.3:a:dotproject:dotproject:0.2.1.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "369174C6-2D7C-44EC-9021-B8DDB1CA753B"
            },
            {
              "criteria": "cpe:2.3:a:dotproject:dotproject:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3862952F-9DE1-471A-A895-A1AFCA3C40F5"
            },
            {
              "criteria": "cpe:2.3:a:dotproject:dotproject:2.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22FFB14E-3C84-4AAE-A04D-221DCDE0F47E"
            },
            {
              "criteria": "cpe:2.3:a:dotproject:dotproject:2.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A2AA0527-4CB6-48BE-AA09-82952570369D"
            },
            {
              "criteria": "cpe:2.3:a:dotproject:dotproject:2.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71C66B24-724C-416F-8678-85A50D70522B"
            },
            {
              "criteria": "cpe:2.3:a:dotproject:dotproject:2.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "935791D0-FFC0-4774-B00F-F83634BA4FBC"
            },
            {
              "criteria": "cpe:2.3:a:dotproject:dotproject:2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "792AA210-2C58-48DE-B2DA-4E58306A339E"
            },
            {
              "criteria": "cpe:2.3:a:dotproject:dotproject:2.1:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "947D5000-870C-4F49-A6BE-68D7E93245AC"
            },
            {
              "criteria": "cpe:2.3:a:dotproject:dotproject:2.1.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A2558DD-A897-48BA-8706-C6790424732D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}